Skip to content
Mounteyes
All guides

How to enable two-factor authentication

7 min readUpdated: Account Security

Two-factor authentication is the single highest-value ten minutes you can spend on your own security. It is also the easiest thing to set up badly, in a way that either fails to protect you or locks you out.

The short version

  • An authenticator app beats SMS: a SIM swap defeats SMS entirely.
  • Save the recovery codes before you finish, or 2FA can lock you out.
  • A passkey or hardware key is the strongest option and cannot be phished.
  • Turn it on for email first — that is the account that resets all the others.

What 2FA fixes

A password can be guessed, reused, phished or found in a breach. Two-factor authentication means a stolen password is no longer enough on its own, which removes the entire value of the most common attack. It is the highest-return security change available to an ordinary person, and it takes about ten minutes per account.

Choosing the second factor

SMS codes are the weakest form, because a SIM swap moves your number to someone else's SIM and the codes follow it. Use SMS only where nothing else is offered — it is still far better than no second factor.

An authenticator app (Google Authenticator, Microsoft Authenticator, Aegis, 1Password, Bitwarden) generates six-digit codes on the device itself, with no network involved. This is the right default for almost everyone: free, offline, and immune to SIM swaps.

A passkey or a hardware security key is the strongest option, and the only one that is genuinely phishing-proof: it is bound to the real website's domain, so a lookalike page cannot use it even if you are fooled. If a service offers passkeys, take them.

Push approvals ("was this you?") are convenient but vulnerable to fatigue attacks, where an attacker triggers prompts repeatedly until someone taps approve. Never approve a prompt you did not personally initiate.

The step nobody should skip: recovery codes

Every service shows a set of one-time backup codes when you enable 2FA. Save them before you click done. If your phone is lost, stolen or wiped and you have no codes, you are in the same recovery queue as someone whose account was actually stolen — which is the single most common way 2FA hurts the person it was meant to protect. Keep them in a password manager, or on paper somewhere only you can reach. Not in a screenshot in your gallery.

Where to turn it on, in order

Email first, always. It resets everything else, so protecting it protects the rest by default. Google: myaccount.google.com/security. Then banking and UPI apps, then anything holding money or payment details.

Then the accounts whose loss would be publicly damaging: Instagram, WhatsApp (Settings, Account, Two-step verification), Facebook, and any account tied to your work or business.

Add the account to your authenticator app while you are in each settings screen, and if the app supports an encrypted backup of its own, turn that on. Rebuilding an authenticator from scratch across a dozen accounts is a bad afternoon.

One warning

A code is only ever entered on a page you navigated to yourself. Attackers phone people mid-attack and ask them to read out the code that just arrived — the code is real, the caller is not. No support agent, bank or platform will ever ask for it. Our tools, and this site, will never ask for it either.

Nothing on this site will ever ask for your password, OTP or recovery codes.

Related guides

Want this handled for you?

Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.

Talk to Our Security Team